Skip to content

Reword our security policy#42953

Merged
jschwe merged 1 commit into
servo:mainfrom
jschwe:security_md
Mar 2, 2026
Merged

Reword our security policy#42953
jschwe merged 1 commit into
servo:mainfrom
jschwe:security_md

Conversation

@jschwe
Copy link
Copy Markdown
Member

@jschwe jschwe commented Mar 2, 2026

In ac24cd6 we started asking for people to use private github security reports, but kept the wording from before, which was related to accepting such reports as public issues.
The wording doesn't make sense in the context of asking people for private reports, so update the wording to reflect that.
This is not a policy change, just making the wording more clear.

Testing: Not required, policy description.

In ac24cd6 we started asking for people
to use **private** github security reports, but kept the wording from
before, which was related to accepting such reports as **public**
issues.
The wording doesn't make sense in the context of asking people for
private reports, so update the wording to reflect that.

Signed-off-by: Jonathan Schwender <[email protected]>
@servo-highfive servo-highfive added the S-awaiting-review There is new code that needs to be reviewed. label Mar 2, 2026
@jschwe
Copy link
Copy Markdown
Member Author

jschwe commented Mar 2, 2026

IMHO it would also make sense to accept security reports via email (Security of email is obviously an issue, but given the scenario and TLS being common, it's probably acceptable and many other projects do accept security reports via email without requiring E2E encryption).

@jschwe jschwe requested a review from mrego March 2, 2026 12:59
@servo-highfive servo-highfive removed the S-awaiting-review There is new code that needs to be reviewed. label Mar 2, 2026
@jschwe jschwe added this pull request to the merge queue Mar 2, 2026
@servo-highfive servo-highfive added the S-awaiting-merge The PR is in the process of compiling and running tests on the automated CI. label Mar 2, 2026
Merged via the queue into servo:main with commit 3037232 Mar 2, 2026
34 checks passed
@jschwe jschwe deleted the security_md branch March 2, 2026 14:41
@servo-highfive servo-highfive removed the S-awaiting-merge The PR is in the process of compiling and running tests on the automated CI. label Mar 2, 2026
simonwuelker added a commit to simonwuelker/servo that referenced this pull request Mar 2, 2026
{"fail_fast": false, "matrix": [{"name": "Linux (WPT)", "workflow": "linux", "wpt": true, "profile": "release", "unit_tests": false, "build_libservo": false, "bencher": false, "coverage": false, "build_args": "", "wpt_args": "", "number_of_wpt_chunks": 20}]}
simonwuelker pushed a commit to simonwuelker/servo that referenced this pull request Mar 3, 2026
In ac24cd6 we started asking for people
to use **private** github security reports, but kept the wording from
before, which was related to accepting such reports as **public**
issues.
The wording doesn't make sense in the context of asking people for
private reports, so update the wording to reflect that.
This is not a policy change, just making the wording more clear.

Testing: Not required, policy description.

Signed-off-by: Jonathan Schwender <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants